Описание
ELSA-2011-0370: wireshark security update (MODERATE)
[1.0.15-1.0.1.el5_6.4]
- Added oracle-ocfs2-network.patch
[1.0.15-1.4]
- fix few security issues
- Resolves: CVE -2011-0024 CVE-2011-0538 CVE-2011-1139 CVE-2011-1140 CVE-2011-1141 CVE-2011-1143 #612240
[1.0.15-1.3]
- recompile with -fno-strict-aliasing
[1.0.15-1.2]
- fix buffer overflow in ENTTEC dissector
- Resolves: #667335
Обновленные пакеты
Oracle Linux 5
Oracle Linux ia64
wireshark
1.0.15-1.0.1.el5_6.4
wireshark-gnome
1.0.15-1.0.1.el5_6.4
Oracle Linux x86_64
wireshark
1.0.15-1.0.1.el5_6.4
wireshark-gnome
1.0.15-1.0.1.el5_6.4
Oracle Linux i386
wireshark
1.0.15-1.0.1.el5_6.4
wireshark-gnome
1.0.15-1.0.1.el5_6.4
Ссылки на источники
Связанные уязвимости
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.
Multiple stack consumption vulnerabilities in the dissect_ms_compresse ...